Skip to content

Daily, weekly and annual operations

The home page is a work queue, not a vanity score. It answers: what needs a decision, what deadline is approaching, what integration is failing, and which evidence is stale?

flowchart LR
  I[Signals: requests, incidents, connector results, source changes] --> Q[Prioritised work queue]
  Q --> T{Triage}
  T -->|Decision needed| A[Assigned owner + checker]
  T -->|Automatable| W[Policy-bound workflow]
  T -->|Uncertain| E[Escalate to legal / security / DPO]
  A --> V[Verify evidence and outcome]
  W --> V
  E --> A
  V --> C[Close or schedule next review]
  C --> M[Daily handover + weekly reconciliation]
  M --> Q

Privacy operations reviews new rights/grievance cases, identity/clarification needs, downstream task failures and Principal messages. Incident command sees active signals and every triggered or uncertain clock. System owners see assigned fulfilment/deletion tasks. Processor managers see incident/subprocessor/contract changes.

Queue columns: severity, entity, case/control, current state, next action, owner, source clock, business target, evidence state and last sync. Default sorting is statutory/contract deadline then risk—not customer value.

  • reconcile failed/late connector tasks and dead letters;
  • review new/changed purposes, notices, vendors and subprocessors;
  • sample identity overrides and mass actions;
  • review open holds and retention exceptions;
  • check contact route and notification delivery health;
  • assess source/change alerts;
  • review support access and break-glass use.

Monthly: evidence freshness, rights/withdrawal latency, deletion completion, processor attestations, access reviews and capacity. Quarterly: sector/legal applicability, incident tabletop, vendor concentration, restore/re-deletion, privileged role certification and executive risk review.

Metrics show numerator/denominator and exclusions. “92% complete” links to the eight missing objects; it is never a compliance grade.

  • full processing/purpose/retention review;
  • contract/subprocessor and transfer review;
  • security risk/control and recovery tests;
  • accessibility and dark-pattern audit;
  • SDF DPIA/audit cycle from designation date if applicable;
  • independent audit and remediation;
  • licence/sector pack review;
  • customer exit rehearsal;
  • open-source dependency/licence and threat-model review.
MetricDefinitionAlert
request clock riskopen cases within configured escalation thresholdowner + DPO
withdrawal propagationcompleted destinations / due destinationspartial past SLO
evidence freshnesscontrols with unexpired passing evidence / applicable controlscritical stale
processor readinesscritical processors with contract, incident and exit testmissing element
retention executiondue records/tasks completed and verifiedbacklog/failed destination
legal config driftactive customers behind approved versionseverity by changed control

Never rank teams by low grievance/incident count; that incentivises suppression. Monitor acknowledgement, decision quality, closure evidence and recurrence instead.

When a connector is down, queue bounded tasks, show source freshness, invoke manual fallback and preserve idempotency. When the control plane is unavailable, customer-side incident/runbook exports provide contacts and forms. On recovery, signed offline actions reconcile without overwriting newer decisions.

Active incidents/cases carry factual summary, clocks, last/next action, open assumptions, communication status, owner and correlation ID. Handover does not transfer accountability silently; the incoming owner acknowledges.